home.social

#darktrace — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #darktrace, aggregated by home.social.

  1. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor

    Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.

    Pulse ID: 6a0b6898afd39bdd2dd6f142
    Pulse Link: otx.alienvault.com/pulse/6a0b6
    Pulse Author: AlienVault
    Created: 2026-05-18 19:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CDN #Chinese #CyberSecurity #DNS #Darktrace #InfoSec #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SideLoading #Trojan #bot #AlienVault

  2. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor

    Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.

    Pulse ID: 6a0b6898afd39bdd2dd6f142
    Pulse Link: otx.alienvault.com/pulse/6a0b6
    Pulse Author: AlienVault
    Created: 2026-05-18 19:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CDN #Chinese #CyberSecurity #DNS #Darktrace #InfoSec #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SideLoading #Trojan #bot #AlienVault

  3. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor

    Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.

    Pulse ID: 6a0b6898afd39bdd2dd6f142
    Pulse Link: otx.alienvault.com/pulse/6a0b6
    Pulse Author: AlienVault
    Created: 2026-05-18 19:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CDN #Chinese #CyberSecurity #DNS #Darktrace #InfoSec #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SideLoading #Trojan #bot #AlienVault

  4. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor

    Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.

    Pulse ID: 6a0b6898afd39bdd2dd6f142
    Pulse Link: otx.alienvault.com/pulse/6a0b6
    Pulse Author: AlienVault
    Created: 2026-05-18 19:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CDN #Chinese #CyberSecurity #DNS #Darktrace #InfoSec #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SideLoading #Trojan #bot #AlienVault

  5. Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor

    Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.

    Pulse ID: 6a0b6898afd39bdd2dd6f142
    Pulse Link: otx.alienvault.com/pulse/6a0b6
    Pulse Author: AlienVault
    Created: 2026-05-18 19:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CDN #Chinese #CyberSecurity #DNS #Darktrace #InfoSec #NET #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SideLoading #Trojan #bot #AlienVault

  6. Threat Landscape Brief - 2026
    Source: Darktrace Annual Threat Report

    Key Metrics:
    • 20% YoY rise in disclosed vulnerabilities
    • 32M phishing emails detected
    • 8.2M targeted VIP accounts
    • 28% increase in QR-based phishing
    • 70% of Americas incidents initiated via stolen credentials
    • Microsoft Azure most targeted cloud
    • Docker environments saw 54.3% honeypot targeting

    Operational shift:
    • Credential abuse > exploit development
    • AI-assisted phishing increasing personalization
    • DMARC bypass at 70% legitimacy pass rate
    • Fresh domains deployed at scale

    Strategic implication:
    Identity telemetry and behavioral analytics are now mission-critical.

    Source: darktrace.com/blog/what-the-da

    Follow @technadu for actionable threat intelligence.
    Share your detection strategy insights below.

    #Infosec #ThreatIntel #IdentitySecurity #Darktrace #CloudSecurity #Azure #PhishingDefense #ZeroTrust #IAM #SecurityOperations #CyberRisk #TechNadu

  7. Threat Landscape Brief - 2026
    Source: Darktrace Annual Threat Report

    Key Metrics:
    • 20% YoY rise in disclosed vulnerabilities
    • 32M phishing emails detected
    • 8.2M targeted VIP accounts
    • 28% increase in QR-based phishing
    • 70% of Americas incidents initiated via stolen credentials
    • Microsoft Azure most targeted cloud
    • Docker environments saw 54.3% honeypot targeting

    Operational shift:
    • Credential abuse > exploit development
    • AI-assisted phishing increasing personalization
    • DMARC bypass at 70% legitimacy pass rate
    • Fresh domains deployed at scale

    Strategic implication:
    Identity telemetry and behavioral analytics are now mission-critical.

    Source: darktrace.com/blog/what-the-da

    Follow @technadu for actionable threat intelligence.
    Share your detection strategy insights below.

    #Infosec #ThreatIntel #IdentitySecurity #Darktrace #CloudSecurity #Azure #PhishingDefense #ZeroTrust #IAM #SecurityOperations #CyberRisk #TechNadu

  8. Threat Landscape Brief - 2026
    Source: Darktrace Annual Threat Report

    Key Metrics:
    • 20% YoY rise in disclosed vulnerabilities
    • 32M phishing emails detected
    • 8.2M targeted VIP accounts
    • 28% increase in QR-based phishing
    • 70% of Americas incidents initiated via stolen credentials
    • Microsoft Azure most targeted cloud
    • Docker environments saw 54.3% honeypot targeting

    Operational shift:
    • Credential abuse > exploit development
    • AI-assisted phishing increasing personalization
    • DMARC bypass at 70% legitimacy pass rate
    • Fresh domains deployed at scale

    Strategic implication:
    Identity telemetry and behavioral analytics are now mission-critical.

    Source: darktrace.com/blog/what-the-da

    Follow @technadu for actionable threat intelligence.
    Share your detection strategy insights below.

    #Infosec #ThreatIntel #IdentitySecurity #Darktrace #CloudSecurity #Azure #PhishingDefense #ZeroTrust #IAM #SecurityOperations #CyberRisk #TechNadu

  9. Threat Landscape Brief - 2026
    Source: Darktrace Annual Threat Report

    Key Metrics:
    • 20% YoY rise in disclosed vulnerabilities
    • 32M phishing emails detected
    • 8.2M targeted VIP accounts
    • 28% increase in QR-based phishing
    • 70% of Americas incidents initiated via stolen credentials
    • Microsoft Azure most targeted cloud
    • Docker environments saw 54.3% honeypot targeting

    Operational shift:
    • Credential abuse > exploit development
    • AI-assisted phishing increasing personalization
    • DMARC bypass at 70% legitimacy pass rate
    • Fresh domains deployed at scale

    Strategic implication:
    Identity telemetry and behavioral analytics are now mission-critical.

    Source: darktrace.com/blog/what-the-da

    Follow @technadu for actionable threat intelligence.
    Share your detection strategy insights below.

    #Infosec #ThreatIntel #IdentitySecurity #Darktrace #CloudSecurity #Azure #PhishingDefense #ZeroTrust #IAM #SecurityOperations #CyberRisk #TechNadu

  10. FBI IC3, Darktrace, and Fortinet are all reporting sharp increases in ATO fraud, holiday phishing, and malicious retail-themed domains.
    • 5,100+ ATO complaints (2025)
    • >$262M in reported losses
    • 620% surge in phishing attempts
    • Fake Amazon/Walmart/Macy’s pages everywhere
    • 18k+ new malicious holiday domains
    • Active exploits hitting Magento, WooCommerce, Oracle EBS

    Stay vigilant this season: confirm URLs manually, use MFA, avoid search-ad logins, and monitor account activity.

    Source: ic3.gov/PSA/2025/PSA251125

    💬 What’s your best advice for preventing ATO and holiday scam victims in 2025?
    Follow TechNadu for more analysis.

    #infosec #cybersecurity #ATO #phishing #holidayfraud #CISO #ThreatIntel #Darktrace #Fortinet #FBI

  11. FBI IC3, Darktrace, and Fortinet are all reporting sharp increases in ATO fraud, holiday phishing, and malicious retail-themed domains.
    • 5,100+ ATO complaints (2025)
    • >$262M in reported losses
    • 620% surge in phishing attempts
    • Fake Amazon/Walmart/Macy’s pages everywhere
    • 18k+ new malicious holiday domains
    • Active exploits hitting Magento, WooCommerce, Oracle EBS

    Stay vigilant this season: confirm URLs manually, use MFA, avoid search-ad logins, and monitor account activity.

    Source: ic3.gov/PSA/2025/PSA251125

    💬 What’s your best advice for preventing ATO and holiday scam victims in 2025?
    Follow TechNadu for more analysis.

    #infosec #cybersecurity #ATO #phishing #holidayfraud #CISO #ThreatIntel #Darktrace #Fortinet #FBI

  12. FBI IC3, Darktrace, and Fortinet are all reporting sharp increases in ATO fraud, holiday phishing, and malicious retail-themed domains.
    • 5,100+ ATO complaints (2025)
    • >$262M in reported losses
    • 620% surge in phishing attempts
    • Fake Amazon/Walmart/Macy’s pages everywhere
    • 18k+ new malicious holiday domains
    • Active exploits hitting Magento, WooCommerce, Oracle EBS

    Stay vigilant this season: confirm URLs manually, use MFA, avoid search-ad logins, and monitor account activity.

    Source: ic3.gov/PSA/2025/PSA251125

    💬 What’s your best advice for preventing ATO and holiday scam victims in 2025?
    Follow TechNadu for more analysis.

    #infosec #cybersecurity #ATO #phishing #holidayfraud #CISO #ThreatIntel #Darktrace #Fortinet #FBI

  13. 🚨 Darktrace uncovers ShadowV2 — a DDoS-for-hire platform blending malware & DevOps.
    🔹 Python + Go malware, Dockerized
    🔹 Exploits AWS EC2 exposed Docker daemons
    🔹 Advanced TTPs: HTTP/2 rapid reset, Cloudflare UAM bypass
    🔹 Operator UI + APIs → “DDoS-as-a-service”
    ⚠️ Threat actors are now building cybercrime with cloud-native design principles.

    👉 Are defenders ready to detect API-driven, containerized attack platforms?

    Follow @technadu for #CyberSecurity + #ThreatIntel updates.

    #ShadowV2 #Darktrace #Botnet #DDoS #CloudSecurity #ContainerSecurity #Malware #CyberCrime

  14. 🚨 Darktrace uncovers ShadowV2 — a DDoS-for-hire platform blending malware & DevOps.
    🔹 Python + Go malware, Dockerized
    🔹 Exploits AWS EC2 exposed Docker daemons
    🔹 Advanced TTPs: HTTP/2 rapid reset, Cloudflare UAM bypass
    🔹 Operator UI + APIs → “DDoS-as-a-service”
    ⚠️ Threat actors are now building cybercrime with cloud-native design principles.

    👉 Are defenders ready to detect API-driven, containerized attack platforms?

    Follow @technadu for #CyberSecurity + #ThreatIntel updates.

    #ShadowV2 #Darktrace #Botnet #DDoS #CloudSecurity #ContainerSecurity #Malware #CyberCrime

  15. 🚨 Darktrace uncovers ShadowV2 — a DDoS-for-hire platform blending malware & DevOps.
    🔹 Python + Go malware, Dockerized
    🔹 Exploits AWS EC2 exposed Docker daemons
    🔹 Advanced TTPs: HTTP/2 rapid reset, Cloudflare UAM bypass
    🔹 Operator UI + APIs → “DDoS-as-a-service”
    ⚠️ Threat actors are now building cybercrime with cloud-native design principles.

    👉 Are defenders ready to detect API-driven, containerized attack platforms?

    Follow @technadu for #CyberSecurity + #ThreatIntel updates.

    #ShadowV2 #Darktrace #Botnet #DDoS #CloudSecurity #ContainerSecurity #Malware #CyberCrime

  16. 🚨 Darktrace uncovers ShadowV2 — a DDoS-for-hire platform blending malware & DevOps.
    🔹 Python + Go malware, Dockerized
    🔹 Exploits AWS EC2 exposed Docker daemons
    🔹 Advanced TTPs: HTTP/2 rapid reset, Cloudflare UAM bypass
    🔹 Operator UI + APIs → “DDoS-as-a-service”
    ⚠️ Threat actors are now building cybercrime with cloud-native design principles.

    👉 Are defenders ready to detect API-driven, containerized attack platforms?

    Follow @technadu for #CyberSecurity + #ThreatIntel updates.

    #ShadowV2 #Darktrace #Botnet #DDoS #CloudSecurity #ContainerSecurity #Malware #CyberCrime

  17. 🚨 Darktrace uncovers ShadowV2 — a DDoS-for-hire platform blending malware & DevOps.
    🔹 Python + Go malware, Dockerized
    🔹 Exploits AWS EC2 exposed Docker daemons
    🔹 Advanced TTPs: HTTP/2 rapid reset, Cloudflare UAM bypass
    🔹 Operator UI + APIs → “DDoS-as-a-service”
    ⚠️ Threat actors are now building cybercrime with cloud-native design principles.

    👉 Are defenders ready to detect API-driven, containerized attack platforms?

    Follow @technadu for #CyberSecurity + #ThreatIntel updates.

    #ShadowV2 #Darktrace #Botnet #DDoS #CloudSecurity #ContainerSecurity #Malware #CyberCrime

  18. We sat down with Nathaniel Jones, VP Security & AI Strategy at Darktrace, to discuss insider tampering, MFA fatigue scams, LLM lateral movement, MaaS operations, and encrypted traffic anomalies.

    🔗 Full Q&A here: technadu.com/detecting-modern-

    #CyberSecurity #Darktrace #AI #MFAFatigue #DevSecOps

  19. We sat down with Nathaniel Jones, VP Security & AI Strategy at Darktrace, to discuss insider tampering, MFA fatigue scams, LLM lateral movement, MaaS operations, and encrypted traffic anomalies.

    🔗 Full Q&A here: technadu.com/detecting-modern-

    #CyberSecurity #Darktrace #AI #MFAFatigue #DevSecOps